Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ivanti
Published: 2025-02-11T15:20:46.680Z
Updated: 2025-02-13T04:55:16.809Z
Reserved: 2024-10-31T19:32:56.456Z
Link: CVE-2024-10644

Updated: 2025-02-11T15:33:24.340Z

Status : Received
Published: 2025-02-11T16:15:38.360
Modified: 2025-02-11T16:15:38.360
Link: CVE-2024-10644

No data.